Upgrade/downgrade considerations for SD-WAN Plugin 2.1 and 2.0.
The following tables list the features that have upgrade or downgrade impact. Make sure you understand all upgrade and downgrade considerations before you upgrade to or downgrade from an SD-WAN plugin 2.1 or 2.0 release. For additional information about the SD-WAN plugin releases, refer to the PAN-OS 10.1 Release Notes and PAN-OS 10.0 Release Notes.
To upgrade from SD-WAN Plugin 2.0.x to 2.1.0, complete the following steps during a maintenance timeframe:
To upgrade from SD-WAN Plugin 2.0.x to 2.0.3, complete the following steps during a maintenance timeframe:
Downgrading the Panorama management server and managed firewalls that currently leverage features that were introduced in PAN-OS 10.0.3 (or later version) or SD-WAN plugin 2.0.1 (or later version) can cause stability issues if you downgrade from the following versions:
Workaround: Before you upgrade to PAN-OS 10.0.3 or SD-WAN plugin 2.0.1, save and export your Panorama and firewall configurations. Then, if you need to downgrade PAN-OS or the SD-WAN plugin to a previous version:
If you did not export and save a Panorama and managed firewall configuration prior to upgrading to PAN-OS 10.0.3 or SD-WAN plugin 2.0.1, then— before you can successfully downgrade to PAN-OS 10.0.2 (or an earlier version) or SD-WAN plugin 2.0.0—you must remove any feature options or configurations that were introduced in PAN-OS 10.0.3 or in SD-WAN plugin 2.0.1.
Remove Private AS
If you change the
Remove Private ASsetting, commit to all SD-WAN cluster nodes, and subsequently downgrade to an SD-WAN Plugin version earlier than 2.0.2, then all configuration related to
Remove Private ASmust be done outside of the SD-WAN plugin or directly on the firewalls.
Full Mesh and DDNS
If you downgrade from SD-WAN Plugin 2.0.1 to an earlier plugin version, the VPN Cluster will not support a mesh configuration or a DDNS configuration. If you had configured a VPN mesh configuration, then you must move the cluster to a Hub-Spoke configuration, configure a hub if you didn't have one,
Remove DDNS Configuration, commit on Panorama, and then push the configuration to your firewalls. If you cannot change the VPN cluster to a Hub-Spoke configuration, then you must delete the entire cluster, commit on Panorama, and then push the configuration to your firewalls before you downgrade.
Recommended For You
Recommended videos not found.